CVE-2026-2754
Summary
| CVE | CVE-2026-2754 |
|---|---|
| State | PUBLISHED |
| Assigner | MHV |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-06 15:16:11 UTC |
| Updated | 2026-06-05 16:39:37 UTC |
| Description | Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to the device can execute HTTP GET requests to TCP port 8080 to retrieve internal network parameters including ECDIS & OT Information, device identifiers, and service status logs. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from 56a186b1-7f5e-4314-ba38-38d5499fccfd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-306 | CWE-306 CWE-306 Missing Authentication for Critical Function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 56a186b1-7f5e-4314-ba38-38d5499fccfd | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Navtor | Navbox | - | All | All | All |
| Operating System | Navtor | Navbox Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cydome.io/vulnerability-advisory-cve-2026-2754-in-navtor-navbox-version... | 56a186b1-7f5e-4314-ba38-38d5499fccfd | cydome.io | Third Party Advisory |
| www.navtor.com/navtor-vendor-statement | 56a186b1-7f5e-4314-ba38-38d5499fccfd | www.navtor.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Cydome Security Ltd (en)
There are currently no legacy QID mappings associated with this CVE.